AP® Cybersecurity Unit 5 flashcardsSecuring Applications and Data
40 cards · about 10 minutes for the whole deck
Flashcard drill
Space flips the card, arrow keys move, and keys 1 to 4 rate how well you knew it.
- Position
- 1 / 40
- Due
- 40
- Mastered
- 0 / 40
This card: New
Flip the card before you rate it.
Administrative privileges
Admin accounts can change system settings and reach almost any file. If a regular user has admin rights and is compromised, so is the whole system.
Topic 5.1: Application and Data Vulnerabilities and Attacks
Data validation
Checking that user input matches what's expected, like a number for a quantity, and rejecting anything else before processing it.
Topic 5.1: Application and Data Vulnerabilities and Attacks
SQL injection
Putting SQL commands and control characters into an input field so the database returns too much data or changes or deletes data.
Topic 5.1: Application and Data Vulnerabilities and Attacks
Cross-site scripting (XSS)
Injecting malicious code into a website so visitors' browsers run it. It can reach data stored in the browser, like logins.
Topic 5.1: Application and Data Vulnerabilities and Attacks
Reflected vs. stored XSS
Reflected (Type I) XSS hides the code in a link the victim clicks. Stored (Type II) XSS saves it on the site, like in a comment, so every visitor runs it.
Topic 5.1: Application and Data Vulnerabilities and Attacks
Buffer overflow
Sending more data than a fixed-size memory buffer holds, so it spills into nearby memory. It can crash a system or run unauthorized code.
Topic 5.1: Application and Data Vulnerabilities and Attacks
Directory traversal
Changing a URL or GET request with ../ sequences to climb out of the web folder and reach sensitive files on the server.
Topic 5.1: Application and Data Vulnerabilities and Attacks
Data states
At rest (stored on a drive), in transit (moving between devices) and in use (being processed). Data must be decrypted to be used.
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Personally identifiable information (PII)
Data that can identify a person, like name, address, Social Security number, birthdate or email. Protected by laws like the Privacy Act of 1974.
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Protected health information (PHI)
Data about a person's health, treatment or health care payments, like test results. Protected under HIPAA (1996).
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Payment card information (PCI)
Data used to process card payments: name, account number, expiration date, address and CVV code. Regulated by the PCI DSS industry standard.
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Role-based access control (RBAC)
Each user gets a role, and each role gets certain access, like only accountants using payroll software.
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Rule-based access control (RuBAC)
Access is allowed or denied by rules, like no database access outside working hours. Usually layered on another model.
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Discretionary access control (DAC)
Owners decide who can access the objects they own, like sharing a file with one person to edit and another to view. Admins can override.
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Mandatory access control (MAC)
Strict rules, set by an outside administrator, control access by levels given to users and objects, as in military classification.
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Bell-LaPadula model
A MAC model: you can't read objects above your level or write to objects below it. Summed up as "write up, read down."
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Least privilege
Giving every user or program exactly the access it needs to do its job, and no more.
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Linux file permissions
Read (r), write (w) and execute (x), set for the owner, the group and others in that order, like rwxr-x---. A dash means no permission.
Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
chmod (numeric)
chmod ### filesets owner, group and others with one digit each: read 4, write 2, execute 1.chmod 640 filegives rw-r-----.Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
chmod (symbolic)
chmodwith u, g, o or a, then + or -, then r, w or x.chmod g+r fileadds read for the group;chmod o-w fileremoves write for others.Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
ls -l and getfacl
ls -lshows a file's permissions. A + at the end means extra permissions are set, which you can see withgetfacl.Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls
Plaintext and ciphertext
Plaintext is the readable information you encrypt. Ciphertext is the scrambled output of the encryption algorithm.
Topic 5.3: Protecting Stored Data with Cryptography
Symmetric encryption
Encryption that uses the same key to encrypt and decrypt. Both sides need that key.
Topic 5.3: Protecting Stored Data with Cryptography
Block vs. stream cipher
A block cipher encrypts fixed-size chunks of bits. A stream cipher encrypts a continuous flow, one element at a time.
Topic 5.3: Protecting Stored Data with Cryptography
AES
The Advanced Encryption Standard, the most common symmetric cipher. It encrypts 128-bit blocks and can use different key lengths.
Topic 5.3: Protecting Stored Data with Cryptography
OpenSSL
A command-line tool that can encrypt and decrypt files with AES or RSA and generate key pairs. AES Crypt is another tool for files.
Topic 5.3: Protecting Stored Data with Cryptography
Asymmetric encryption
Encryption with a key pair: one key encrypts and only the other can decrypt. It lets people communicate securely without sharing a key first.
Topic 5.4: Asymmetric Cryptography
Public and private keys
To send someone a secret, encrypt with their public key; only their private key can decrypt it. If a private key leaks, make a new pair.
Topic 5.4: Asymmetric Cryptography
Key length and keyspace
An n-bit key has 2ⁿ possible keys, and random guessing finds it in 2ⁿ⁻¹ guesses on average. Each extra bit doubles the keyspace.
Topic 5.4: Asymmetric Cryptography
Comparing key lengths
Compare key lengths only within one algorithm: AES-256 beats AES-128 and RSA-4096 beats RSA-2048, but RSA and AES lengths can't be compared.
Topic 5.4: Asymmetric Cryptography
RSA and ECC
Two common asymmetric algorithms, RSA and elliptic curve cryptography. Asymmetric encryption also powers digital signatures and certificates.
Topic 5.4: Asymmetric Cryptography
Secure by design
Building security into every phase of making a product. Companies own customers' security outcomes, are open about problems and put security-first leaders in charge.
Topic 5.5: Protecting Applications
Secure by default
Security features come turned on out of the box, so a product is safe to use without extra setup.
Topic 5.5: Protecting Applications
Control characters
Characters an app uses to wrap user input, like the single quote, double quote and semicolon. Attackers slip them into input to change commands.
Topic 5.5: Protecting Applications
Input sanitization
Checking input against what's expected and removing or rejecting dangerous characters. It blocks many SQL injection, XSS and directory traversal attacks.
Topic 5.5: Protecting Applications
Accounting
Recording and monitoring user activity, like who opened, copied, moved or deleted which data. Its logs reveal unusual access.
Topic 5.6: Detecting Attacks on Data and Applications
Honeypot
A fake file that looks valuable, like fake card numbers. No one should open it, so any access triggers an alert right away.
Topic 5.6: Detecting Attacks on Data and Applications
File hash check
Hash a file, save the result, and hash it again later. A different hash means the file changed. Tools:
sha256sum,Get-FileHash,shasum -a 256.Topic 5.6: Detecting Attacks on Data and Applications
Data loss prevention (DLP)
A paid service that watches how data are accessed, used and sent across an organization to catch suspicious activity as it happens.
Topic 5.6: Detecting Attacks on Data and Applications
Web log attack indicators
Quotes, OR 1=1, -- and SQL words suggest SQL injection; HTML script tags suggest XSS; very long requests suggest buffer overflow; ../ suggests directory traversal.
Topic 5.6: Detecting Attacks on Data and Applications